We’re happy to announce the release of ClassicPress 2.7.1.
This is a security release.
Security Fixes
- Users: Ensure a proper email address is used before sending email confirmations.
- Formatting: Prevent stack overflow in safecss_filter_attr.
- Multisite: Enforce the active signup policy for existing users.
- HTTP API: Improve compliance with IPv4 Special-Purpose Address Space.
- Users: Prevent Usernames from mangling HTML.
- Comments: Exclude notes from comment feed queries.
- Canonical: Only redirect for publicly viewable post types.
- Administration: When wp_is_large_user_count(), ensure that the post author is always added to author dropdown.
- Media: Prevent loading images into Imagick which might be PostScript.
Contributors
In no particular order the following people have contributed to this ClassicPress release:
ClassicPress props
Matt Robinson, Simone Fioravanti, Tim Kaye.
ClassicPress committers (in random order)
Matt Robinson.
WordPress committers
John Blackbourn, Adam Silverstein, Anthony Burchell.
WordPress props
ehtis, dmsnell, jeremyfelt, westonruter, SergeyBiryukov, aaroncampbell, jorbin, batmoo, johnbillion, lancewillett, tyxla, vortfu, xknown, adamsilverstein, swissspidy, antpb, sippis, gitlost, joemcgill, joedolson, launchinteractive, emirpprime, mwtsn, ceer, maysi, madejackson, 6adminit, costdev, oglekler, wildworks, mukesh27, odkdn1, khokansardar, peterwilsoncc, lucasbustamante, paulkevan, desrosj, jonsurrell.
Download this release
| New sites | DownloadClassicPress-release-2.7.1.zipand follow the installation instructions. |
|---|---|
| Existing WordPress sites | Download the migration plugin and follow the migration instructions. |
| Existing ClassicPress sites | Use the built-in update mechanism (more info). |
Full changelog
The full changelog is available on GitHub.